Samba
Deploy samba server.
Ansible hosts group: samba
Variables
| Option | Type | Description | Default |
|---|---|---|---|
cs_samba_share_docs_root | string | Path to the share root folder | /srv/samba |
cs_samba_cluster_name | string | Cluster name | {{ cs_cluster_name }} |
cs_samba_shares | dict | Samba shares |
cs_samba_shares
cs_samba_shares:
docs (Name of the share):
path: (Optional) else {{ cs_samba_share_docs_root }}/{{ share_name }}, like /srv/samba/docs
browseable: (Optional) else yes
writable: (Optional) else yes
read_only: (Optional) else no
guest_ok: (Optional) else no
public: (Optional) else no
create_mask: (Optional) else 0664
directory_mask: (Optional) else 0775
A share without path gets its directory created under cs_samba_share_docs_root (mode 0775). A share
with an explicit path must already exist as a directory, or the run fails.
Vault configurations
- key:
{{ cs_project_code }}/application-deployer/clusters/{{ Lab Name or Cluster name }}/hosts/{{ hostname }}/apps/samba/config
{
"shares": {
"<(Optional) Share Name, `access` is optional>": {
"access": {
"groups": {
"<(Optional) Group Name 1>": {},
"<(Optional) Group Name 2>": {}
},
"users": {
"<(Optional) User Name 1, This user will be added to `smbshare` group>": {
"password": "(Optional) samba password"
},
"<(Optional) User Name 2, This user will be added to `smbshare` group>": {}
}
}
}
}
}
Cleanup (dangerously_cleanup_samba)
Destructive. Only runs when this exact tag is passed explicitly (it is intentionally excluded
from the plain samba tag) and permanently removes Samba from the host:
- Stops and disables the
smbdandnmbdsystemd units, tolerating hosts where Samba was never installed. - Deletes the UFW allow rules opened for ports 137, 138, 139, and 445.
- Purges the
sambaandcifs-utilspackages (apt ... purge: true), autoremoves any dependencies left unused, and autocleans the local.debpackage cache. Purging removes/etc/samba/smb.confalong with it.
Share data under cs_samba_share_docs_root (/srv/samba) and on the mounted disks, along with the
smbshare group and any per-share OS users, are left untouched.
Tags
samba: Deploy samba server.dangerously_cleanup_samba: Destructive. Stops and disables Samba's systemd services, closes its UFW ports, and purges thesamba/cifs-utilspackages. Never included by the plainsambatag.
Deployment
uv sync --all-extras --all-packages --no-progress
uv --offline run --no-sync --no-progress ansible-galaxy install -r requirements.yml
uv --offline run --no-sync --no-progress ansible-playbook playbook.yml --tags samba